Blind SQL Injection in admin panel PHP-Fusion <= v7.02.07

Posted by Manuel Garcia Cardenas on Oct 05

=============================================
MGC ALERT 2015-002
– Original release date: September 18, 2015
– Last revised: October 05, 2015
– Discovered by: Manuel García Cárdenas
– Severity: 7,1/10 (CVSS Base Score)
=============================================

I. VULNERABILITY
————————-
Blind SQL Injection in admin panel PHP-Fusion <= v7.02.07

II. BACKGROUND
————————-
PHP-Fusion is a lightweight open…